Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Secure AI in the browser: what identity teams need to control


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 18004
Topic starter  

TL;DR: Browser-based AI visibility is emerging as an identity control problem, not just a usage reporting issue, because workers are now interacting with AI apps, shadow SaaS, and unmanaged identities inside the browser where traditional endpoint and network tools have limited coverage, according to Push Security. The governance gap is that existing IAM, SaaS, and browser controls rarely give teams a complete view of who or what is using AI and with what authority.

NHIMG editorial — based on content published by Push Security: browser attacks and AI visibility in the workforce

By the numbers:

Questions worth separating out

Q: How should security teams govern employee use of public AI tools in the browser?

A: They should treat browser AI use as an identity and data-control problem, not just an acceptable-use issue.

Q: Why do browser-based AI extensions create identity risk for enterprise users?

A: They create identity risk because they can sit inside the authenticated session and see the same bearer tokens the user relies on.

Q: What signals show that AI access is outpacing governance?

A: The clearest signals are broad inherited permissions, large volumes of stale guest access, and inconsistent file classification across teams.

Practitioner guidance

  • Instrument browser visibility for AI services Capture browser-level activity for AI apps, SaaS sessions, and unmanaged access paths so that security teams can see usage that never passes through central approval workflows.
  • Classify AI apps in identity governance records Treat browser-discovered AI services as governed applications with owners, access rules, and offboarding responsibility rather than as informal user tools.
  • Correlate browser telemetry with account takeover signals Use browser telemetry alongside identity alerts to identify consent abuse, token theft, and suspicious session behaviour that can lead to AI and SaaS compromise.

What's in the full article

Push Security's full blog post covers the operational detail this post intentionally leaves for the source:

  • Browser attack techniques and detection examples that show how AI usage appears in real session telemetry.
  • Product-specific browser visibility workflows for investigating AI, shadow SaaS, and unmanaged identity activity.
  • Implementation details for turning browser observations into response and governance actions.
  • Examples of the exact telemetry patterns Push uses to identify risky browser-based identity behaviour.

👉 Read Push Security's analysis of browser-based AI visibility and identity control →

Secure AI in the browser: what identity teams need to control?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 17593
 

Browser AI visibility is now an IAM problem as much as a browser-security problem. When AI services are used through the browser, the identity layer is where approval, session state, and data movement converge. That means security teams cannot treat AI usage as separate from access governance, because the browser is often the actual control surface. The practical conclusion is that AI governance must sit inside identity operations, not beside them.

A few things that frame the scale:

  • The 2024 ESG Report found that 72% of organisations have experienced or suspect a breach of non-human identities, according to The 2024 ESG Report: Managing Non-Human Identities.
  • Enterprises that have experienced a compromised NHI averaged 2.7 separate incidents in the past 12 months, which shows how quickly unmanaged identity exposure can repeat.

A question worth separating out:

Q: What should IAM teams do when browser telemetry reveals shadow AI usage?

A: Reconcile the service to an owner, decide whether it belongs in approved access pathways, and ensure offboarding and review rules apply to every linked account and session. If the service cannot be governed, the issue is not visibility alone but an access path that should not remain open.

👉 Read our full editorial: AI use in the workforce is a browser identity problem, not a headcount one



   
ReplyQuote
Share: